From 88358d11d69853ea930e2da2389910bb8fd26328 Mon Sep 17 00:00:00 2001 From: Marlon Costa Date: Thu, 6 Aug 2026 19:27:42 -0300 Subject: [PATCH 1/2] docs(security): Semgrep triage inventory (6 findings) Inventario dos findings da plataforma Semgrep com regra, arquivo e linha por achado. Totais: high 0, medium 5, low 1 (high confidence: 4) Classes: Insecure Configuration x4; Improper Authentication x1; Code Injection x1 Bead: mro-p57t.4 Nenhuma alteracao de codigo de producao. Findings SAST exigem analise caso a caso do fluxo de dados. --- docs/security/semgrep-triage.md | 39 +++++++++++++++++++++++++++++++++ 1 file changed, 39 insertions(+) create mode 100644 docs/security/semgrep-triage.md diff --git a/docs/security/semgrep-triage.md b/docs/security/semgrep-triage.md new file mode 100644 index 00000000..33c0d48d --- /dev/null +++ b/docs/security/semgrep-triage.md @@ -0,0 +1,39 @@ +# Triagem Semgrep — flext-sh/flext-cli + +Gerado do dump da plataforma Semgrep (deployment `datacosmos`, 2026-08-06). + +Bead de rastreio: `mro-p57t.4` + +## Resumo + +**6 findings** — high 0, medium 5, low 1 +Confiança: high 4, medium 0, low 2 + +| regra | achados | +|---|---| +| `package_managers.dependabot.dependabot-missing-cooldown.dependabot-missing-cooldown` | 3 | +| `package_managers.uv.uv-missing-dependency-cooldown.uv-missing-dependency-cooldown` | 1 | +| `python.django.security.audit.unvalidated-password.unvalidated-password` | 1 | +| `python.lang.security.audit.dangerous-annotations-usage.dangerous-annotations-usage` | 1 | + +## Findings + +Coluna **Decisão** a preencher: `corrigir` / `falso-positivo` / `risco-aceito`. + +| # | sev | conf | regra | arquivo | linha | Decisão | +|---|---|---|---|---|---|---| +| 1 | medium | high | `dependabot-missing-cooldown` | `.github/dependabot.yml` | 4 | | +| 2 | medium | high | `dependabot-missing-cooldown` | `.github/dependabot.yml` | 11 | | +| 3 | medium | high | `dependabot-missing-cooldown` | `.github/dependabot.yml` | 18 | | +| 4 | medium | high | `uv-missing-dependency-cooldown` | `pyproject.toml` | 586 | | +| 5 | medium | low | `unvalidated-password` | `src/flext_cli/_utilities/_xlxx/xlsx_protection.py` | 65 | | +| 6 | low | low | `dangerous-annotations-usage` | `src/flext_cli/_utilities/model_commands.py` | 89 | | + +## Como triar + +1. Abrir `arquivo:linha` e seguir o fluxo até o sink. +2. Classificar: **corrigir** (entrada externa alcança o sink), **falso-positivo** (registrar via `nosemgrep` ou `.semgrepignore` com justificativa), **risco-aceito** (com prazo de revisão). +3. Priorizar findings high com confidence=high. + +Dados brutos: `~/semgrep-violations/by-repo/flext-sh__flext-cli.json` + From bc224f536116e9fe0808562938324068b2568cc9 Mon Sep 17 00:00:00 2001 From: Marlon Costa Date: Thu, 6 Aug 2026 20:00:11 -0300 Subject: [PATCH 2/2] docs(security): enrich Semgrep triage with code snippets and full rule messages Cada achado agora traz: - codigo real numerado extraido da worktree (linha >>> = sink) - mensagem completa da regra (descricao do problema e do fix) - CWE/classe de vulnerabilidade e effort onde disponivel --- docs/security/semgrep-triage.md | 129 ++++++++++++++++++++++++++++---- 1 file changed, 114 insertions(+), 15 deletions(-) diff --git a/docs/security/semgrep-triage.md b/docs/security/semgrep-triage.md index 33c0d48d..c811995f 100644 --- a/docs/security/semgrep-triage.md +++ b/docs/security/semgrep-triage.md @@ -2,7 +2,7 @@ Gerado do dump da plataforma Semgrep (deployment `datacosmos`, 2026-08-06). -Bead de rastreio: `mro-p57t.4` +Bead: `mro-p57t.4` ## Resumo @@ -16,24 +16,123 @@ Confiança: high 4, medium 0, low 2 | `python.django.security.audit.unvalidated-password.unvalidated-password` | 1 | | `python.lang.security.audit.dangerous-annotations-usage.dangerous-annotations-usage` | 1 | +## Como usar + +Cada finding traz a **mensagem completa da regra** (o Semgrep descreve o problema e frequentemente o fix), o **código real** (linha `>>>`), classe de vulnerabilidade, CWE/OWASP. +**Decisão**: `corrigir` / `falso-positivo` (`nosemgrep` ou `.semgrepignore` com justificativa) / `risco-aceito`. Priorizar high com confidence=high. + ## Findings -Coluna **Decisão** a preencher: `corrigir` / `falso-positivo` / `risco-aceito`. +### 1 · 🟡 MEDIUM · conf high · `package_managers.dependabot.dependabot-missing-cooldown.dependabot-missing-cooldown` +**Classe**: Insecure Configuration · **Local**: `.github/dependabot.yml:4` + +> This Dependabot configuration does not set a cooldown period. Newly published packages can be malicious or unstable. Add a `cooldown` block with `default-days: 7` to each `package-ecosystem` entry under `updates` to wait 7 days before proposing updates to newly published package versions. Reference: https://docs.github.com/en/code-security/dependabot/dependabot-version-updates/configuration-option + +```yaml + 1 # Generated by `flext-infra codegen conform` for flext-cli — DO NOT EDIT. + 2 version: 2 + 3 updates: +>>> 4 - package-ecosystem: github-actions + 5 directory: / + 6 schedule: + 7 interval: weekly + 8 open-pull-requests-limit: 5 +``` + +**Decisão**: + +### 2 · 🟡 MEDIUM · conf high · `package_managers.dependabot.dependabot-missing-cooldown.dependabot-missing-cooldown` +**Classe**: Insecure Configuration · **Local**: `.github/dependabot.yml:11` + +> This Dependabot configuration does not set a cooldown period. Newly published packages can be malicious or unstable. Add a `cooldown` block with `default-days: 7` to each `package-ecosystem` entry under `updates` to wait 7 days before proposing updates to newly published package versions. Reference: https://docs.github.com/en/code-security/dependabot/dependabot-version-updates/configuration-option + +```yaml + 7 interval: weekly + 8 open-pull-requests-limit: 5 + 9 labels: [dependencies, github-actions] + 10 +>>> 11 - package-ecosystem: devcontainers + 12 directory: / + 13 schedule: + 14 interval: weekly + 15 open-pull-requests-limit: 5 +``` + +**Decisão**: + +### 3 · 🟡 MEDIUM · conf high · `package_managers.dependabot.dependabot-missing-cooldown.dependabot-missing-cooldown` +**Classe**: Insecure Configuration · **Local**: `.github/dependabot.yml:18` + +> This Dependabot configuration does not set a cooldown period. Newly published packages can be malicious or unstable. Add a `cooldown` block with `default-days: 7` to each `package-ecosystem` entry under `updates` to wait 7 days before proposing updates to newly published package versions. Reference: https://docs.github.com/en/code-security/dependabot/dependabot-version-updates/configuration-option + +```yaml + 14 interval: weekly + 15 open-pull-requests-limit: 5 + 16 labels: [dependencies, devcontainers] + 17 +>>> 18 - package-ecosystem: pip + 19 directory: / + 20 schedule: + 21 interval: weekly + 22 open-pull-requests-limit: 5 +``` + +**Decisão**: + +### 4 · 🟡 MEDIUM · conf high · `package_managers.uv.uv-missing-dependency-cooldown.uv-missing-dependency-cooldown` +**Classe**: Insecure Configuration · **Local**: `pyproject.toml:586` + +> This pyproject.toml configures uv but does not set a dependency cooldown. Newly published packages can be malicious or unstable. Add `exclude-newer = "7 days"` under `[tool.uv]` to wait 7 days before resolving newly published package versions. Added in: 0.9.17 Reference: https://docs.astral.sh/uv/concepts/resolution/#dependency-cooldowns + +```toml + 582 all = true + 583 in_place = true + 584 sort_first = ["build-system", "dependency-groups", "project", "tool"] + 585 +>>> 586 [tool.uv] + 587 constraint-dependencies = ["gitpython>=3.1.55", "setuptools>=83"] + 588 link-mode = "copy" + 589 + 590 [[tool.uv.exclude-dependencies]] +``` + +**Decisão**: + +### 5 · 🟡 MEDIUM · conf low · `python.django.security.audit.unvalidated-password.unvalidated-password` +**Classe**: Improper Authentication · **Local**: `src/flext_cli/_utilities/_xlxx/xlsx_protection.py:65` + +> The password on 'protection' is being set without validating the password. Call django.contrib.auth.password_validation.validate_password() with validation functions before setting the password. See https://docs.djangoproject.com/en/3.0/topics/auth/passwords/ for more information. + +```python + 61 if plan.credential is not None: + 62 if plan.credential.kind == "legacy_hash": + 63 protection.set_password(plan.credential.value, already_hashed=True) + 64 else: +>>> 65 protection.set_password(plan.credential.value) + 66 return r[bool].ok(True) + 67 + 68 + 69 __all__: tuple[str, ...] = ("FlextCliUtilitiesXlsxProtection",) +``` + +**Decisão**: -| # | sev | conf | regra | arquivo | linha | Decisão | -|---|---|---|---|---|---|---| -| 1 | medium | high | `dependabot-missing-cooldown` | `.github/dependabot.yml` | 4 | | -| 2 | medium | high | `dependabot-missing-cooldown` | `.github/dependabot.yml` | 11 | | -| 3 | medium | high | `dependabot-missing-cooldown` | `.github/dependabot.yml` | 18 | | -| 4 | medium | high | `uv-missing-dependency-cooldown` | `pyproject.toml` | 586 | | -| 5 | medium | low | `unvalidated-password` | `src/flext_cli/_utilities/_xlxx/xlsx_protection.py` | 65 | | -| 6 | low | low | `dangerous-annotations-usage` | `src/flext_cli/_utilities/model_commands.py` | 89 | | +### 6 · ⚪ LOW · conf low · `python.lang.security.audit.dangerous-annotations-usage.dangerous-annotations-usage` +**Classe**: Code Injection · **Local**: `src/flext_cli/_utilities/model_commands.py:89` -## Como triar +> Annotations passed to `typing.get_type_hints` are evaluated in `globals` and `locals` namespaces. Make sure that no arbitrary value can be written as the annotation and passed to `typing.get_type_hints` function. -1. Abrir `arquivo:linha` e seguir o fluxo até o sink. -2. Classificar: **corrigir** (entrada externa alcança o sink), **falso-positivo** (registrar via `nosemgrep` ou `.semgrepignore` com justificativa), **risco-aceito** (com prazo de revisão). -3. Priorizar findings high com confidence=high. +```python + 85 setattr(command, "__signature__", signature) + 86 command.__annotations__ = { + 87 parameter.name: parameter.annotation for parameter in parameters + 88 } +>>> 89 command.__annotations__["return"] = t.JsonValue + 90 return command + 91 + 92 @staticmethod + 93 def model_source_data( +``` -Dados brutos: `~/semgrep-violations/by-repo/flext-sh__flext-cli.json` +**Decisão**: